Skip to content

Releases: zeroscience/WaSAP

Release list

WaSAP 2.5.1

Choose a tag to compare

@zeroscience zeroscience released this 01 Oct 08:53
ca176f4

SAP-specific scan checks for Burp Suite, built on the Montoya API.

Three checks registered with Burp Scanner:

  • Passive (PER_REQUEST): SAP fingerprints, NetWeaver/proprietary header disclosure, SAP session cookie flag checks, ABAP/J2EE verbose errors.
  • Active per host (PER_HOST): 58-entry SAP endpoint catalog plus content/version-verified CVE probes (CVE-2025-31324 Visual Composer, also flagging the chained CVE-2025-42999; CVE-2022-22536 ICMAD; CVE-2020-6287 RECON; CVE-2020-6207 Solution Manager EEM; CVE-2017-12637 AS Java Scheduler traversal; catalog tags CVE-2020-6308 LMXML and CVE-2010-5326 Invoker) and /sap/public/info system-info extraction.
  • Active per insertion point (PER_INSERTION_POINT): SAP-specific parameter checks only.

Findings are raised as standard Burp audit issues and require SAP corroboration before being reported, to avoid false positives on non-SAP hosts. Requires Burp Suite with the Montoya API. See CHANGELOG.md.

Build from source: ./gradlew jar